Signal’s 8.30 release completes the rollout of end-to-end encrypted backups across Android, iOS, Linux, macOS, and Windows — and it does so by offering two sharply different ways to store your chat history.
Signal version 8.30: cross-platform encrypted backups
Signal published version 8.30 to bring its backups feature — first introduced on Android nearly a year ago — to iOS and desktop platforms and to standardize Android’s implementation on a single cross-platform format. The update finishes what Signal describes as the first phase of the backups project and includes a new direct iPhone-to-iPhone transfer mode in the 8.30 iOS client that uses a local end-to-end encrypted Wi‑Fi Aware link intended to improve transfer speed and reliability.
Hosted backups versus on-device local backups
The backup system now supports two distinct options. Signal-hosted backups are available with explicit limits for free users and expanded quotas for paid plans: hosted backups are limited to 45 days of media and 128 KB per message for free users, while paid plans receive up to 100 GB. The alternative is on-device, local backups, which Signal says have no size restrictions. Both backup methods are encrypted and require a recovery key to decrypt stored data.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleKey architecture, Trusted Execution Environment, and attacker attention
While both backup types require a recovery key, Signal notes an important architectural difference for hosted backups: they use a supplemental key that rotates daily inside a Trusted Execution Environment (TEE) to provide additional protection and forward secrecy. By contrast, Signal also warns that an on-device backup recovery key can decrypt all past backup files it encrypted, regardless of where those files are stored. The company reports that threat actors "have already taken notice of the key's value and incorporated it into their targeting scope" shortly after Signal introduced the backup feature.
Media handling, disappearing messages, and device linking
Signal changed how media is stored in backups: media is now separated from the backup archive and duplicate files are stored only once to reduce excessive backing up and syncing. When linking a new device from the primary device, the new device will retrieve older attachments that are missing from the chat. Paying users gain an extra option to purge old media from local storage while keeping thumbnails; full media can then be automatically retrieved from hosted backups.
The backup system explicitly ignores disappearing messages set to vanish within 24 hours on both hosted and on-device backups, preventing those messages from being included in archives. If a user has both hosted and on-device backups, Signal notes that the hosted backup does not wipe the on-device backup. During restoration, expired disappearing messages from local backups will be skipped.
What this means for technologists, end users, and adversaries
- Technologists and security teams: The TEE-backed daily-rotating supplemental key for hosted backups is a concrete architectural control Signal is using to limit long-term key exposure for hosted data. At the same time, the fact that an on-device recovery key can decrypt all prior local backups is a design detail that teams integrating Signal into enterprise or managed-device workflows should account for when defining backup and key-handling policies.
- End users and paying customers: Users now have a tradeoff between convenience and storage limits: hosted backups offer cross-device retrieval and server-side media retention subject to quota rules, while on-device backups remove size limits but centralize decryption authority in a single recovery key. Paying users get the additional option to purge local media while retaining thumbnails and fetching full media from hosted backups.
- Adversaries and threat actors: Signal reports that threat actors quickly added the recovery key to their targeting scope after the feature's initial rollout, underlining the operational risk attached to any key that can decrypt multiple past backups, regardless of where those backups reside.
Signal says the 8.30 rollout completes the first phase of its backups project; its engineers will now focus on improving non-backup systems. The record the company has set with this release is twofold: broader, faster cross-device recovery and a clear mapping of where sensitive recovery authority resides — both the rotating TEE-backed element for hosted backups and a single, powerful recovery key for on-device archives.




